首页> 外国专利> Client token storage for cross-site request forgery protection

Client token storage for cross-site request forgery protection

机译:客户端令牌存储,用于跨站点请求伪造保护

摘要

Systems and methods can secure against cross-site request forgery using client-side token storage. A client browser can initiate an action associated with a first web service and generate a token. The token may be stored in client-side storage at the computing device. An indicator of the action may also be stored within the client-side storage. A return link, associated with a passed copy of the token, may be generated. The client may perform the redirect and return to the first web service according to the return link. The passed copy of the token can be extracted from the return link. The indicator of the action and the stored token may be loaded from the client storage. The passed copy of the token and the stored token may be compared. The action according to the indicator of the action may be performed in response to the comparison matching.
机译:系统和方法可以使用客户端令牌存储来防止跨站点请求伪造。客户端浏览器可以启动与第一Web服务关联的操作并生成令牌。令牌可以存储在计算设备处的客户端存储中。动作的指示符也可以存储在客户端存储中。可以生成与令牌的传递副本关联的返回链接。客户端可以执行重定向,并根据返回链接返回第一网络服务。可以从返回链接中提取传递的令牌副本。动作的指示符和存储的令牌可以从客户端存储中加载。可以比较传递的令牌副本和存储的令牌。可以响应于比较匹配来执行根据动作的指示符的动作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号